aboutcode-org / aboutcode-org/vulnerablecode

Apache HTTPD does NOT use Maven versioning

未關閉
#579 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
bug Data collection data-quality versioning
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

The current code use the univers MavenVersion for httpd advisories. This is incorrect.
The semantics and range notation from httpd are NOT the Maven ones.
See https://httpd.apache.org/security/json/CVE-2000-1204.json for instance:
```JSON
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Apache Software Foundation",
"product": {
"product_data": [
{
"product_name": "Apache HTTP Server",
"version": {
"version_data": [
{
"version_name": "1.3",
"version_affected": "=",
"version_value": "1.3.12"
},
{
"version_name": "1.3",
"version_affected": "=",
"version_value": "1.3.11"
},
{
"version_name": "1.3",
"version_affected": "=",
"version_value": "1.3.9"
}
]
}
}
]
}
}
]
}

```

And per https://archive.apache.org/dist/httpd/ the version seem to be mostly semver with some pre-release extra but these is NOT maven.

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。